Law / Kenya

Data Protection (General) Regulations, 2021

Data Protection (General) Regulations, 2021 (Legal Notice No. 263 of 2021), regs. 7, 10, 37, 49-50

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 14 January 2022.

A breach notification rule binding public and private bodies.

As of 4 September 2026.

What it requires

  • Conduct a data protection impact assessment before undertaking automated decision-making or profiling that has a legal or similarly significant effect on a data subject.
  • Notify a data subject in writing within seven days of declining a rectification request, or within fourteen days of declining a restriction request, giving reasons.

Who checks it

Audit expectation

continuous

Who audits it

Self

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The Data Protection (General) Regulations, 2021 elaborate the Act's breach-notification duty and add operational detail on data-subject requests, including a fourteen-day deadline to notify a data subject in writing of a refused restriction request and a seven-day deadline for a refused rectification request.

Regulation 49 requires a data protection impact assessment before processing that includes automated decision-making or profiling with a legal or similarly significant effect, among other high-risk processing operations.

When LexLint raises it

  • crawls_web
  • trains_models
  • high_risk_decisions

Read the law

official consolidated Regulations text, Kenya Law (National Council for Law Reporting)

Back to the example  ·  Lint your app